Vidar Infostealer Being Spread through Phishing Emails
ID: 3bfac531-02c8-5d35-9aff-201e31f8a9f7
STIX ID: report--3bfac531-02c8-5d35-9aff-201e31f8a9f7
Feed Name: ASEC
Vidar infostealer is actively distributed via phishing in H1 2026 using document-disguised executables and a Go-based packer; the analyzed variants employ anti-analysis techniques, retrieve C2 addresses via Telegram and Steam profiles (DDR), and exfiltrate browser credentials, cookies, crypto wallet files, messaging tokens and other sensitive files. The report includes configuration and mode details, examples of exfiltrated artifacts, and IOCs (hashes, URLs, FQDNs) to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
